Junglewise Threat Intelligence

CVE-2026-38571: Tenda N300 F3 unauthenticated UART console and cleartext credential storage

CVE-2026-38571 · Severity: info · CVSS 6.8 · Published 2026-06-26

Technologies: Tenda F3. Vendors: Tenda.

Executive brief

The Tenda N300 F3 wireless router contains a security flaw where its internal diagnostic port is left unprotected. An individual with physical access to the device can connect a simple adapter to this port to bypass all security, viewing the Wi-Fi passwords in plain text. Additionally, they can gain full control over the device's memory, potentially allowing them to intercept network traffic or compromise other connected systems.

Technical details

The Tenda N300 F3 (firmware V603) router exposes an unauthenticated command-line console via the on-board UART serial header. This console lacks any login requirements, allowing a physically proximate attacker to access the device's boot logs and NVRAM, which contain WPA2 credentials in cleartext. Furthermore, the console provides 'rr' (read) and 'wr' (write) commands that allow for arbitrary 32-bit memory access without authentication. This can be exploited to modify device behavior or extract sensitive data from memory. As of the disclosure date, no patch is available.

Affected products

  • Tenda Technology Co., Ltd. Wireless N300 Easy Setup Router F3 V603 (eCos based)

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: advisory

References

Related threats